ATT&CKReferencesTrendMicro BKDR_URSNIF.SM

TrendMicro BKDR_URSNIF.SM

Sioting, S. (2013, June 15). BKDR_URSNIF.SM. Retrieved June 5, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples8

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareUrsnif

Ursnif has collected files from victim machines, including certificates and cookies.

T1012
Query Registry
MalwareUrsnif

Ursnif has used Reg to query the Registry for installed programs.

T1057
Process Discovery
MalwareUrsnif

Ursnif has gathered information about running processes.

T1105
Ingress Tool Transfer
MalwareUrsnif

Ursnif has dropped payload and configuration files to disk. Ursnif has also been used to download and execute additional payloads.

T1112
Modify Registry
MalwareUrsnif

Ursnif has used Registry modifications as part of its installation routine.

T1113
Screen Capture
MalwareUrsnif

Ursnif has used hooked APIs to take screenshots.

T1185
Browser Session Hijacking
MalwareUrsnif

Ursnif has injected HTML codes into banking sites to steal sensitive online banking information (ex: usernames and passwords).

T1547.001
Registry Run Keys / Startup Folder
MalwareUrsnif

Ursnif has used Registry Run keys to establish automatic execution at system startup.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.